August 2026
The SAND OFT's own approveAndCall let an attacker name themselves LayerZero delegate, forge inbound verification, mint 329 trillion unbacked SAND on Base and empty the Ethereum adapter.
Read the full analysis →Allbridge's new CCTP router on Base credited a forged Circle message as a real deposit. The attacker booked a phantom $1M, flash-loaned the shortfall and took the router's entire 191,156 USDC.
Read the full analysis →An attacker chained six MAYAChain bugs so a false theft alert paid an uncapped 49.45M CACAO subsidy into a pool holding 0.11 LINK, then took 99.93% of it and withdrew 48.87M CACAO.
Read the full analysis →An attacker minted about 4 billion ONE, inflating Harmony's supply by roughly 26%, while a masked totalSupply reading delayed detection and 97% of the tokens reached exchanges before any freeze.
Read the full analysis →A missing nHeight check in Ravencoin's KAWPOW validation let attackers append forged blocks with no real proof-of-work, forcing RVN freezes and a rollback to block 4,487,775.
Read the full analysis →The ten biggest DeFi hacks of January through July 2026, ranked by amount lost: KelpDAO's $292M bridge exploit, Drift's $285M key compromise, and eight more, with the root cause of each and the operational-failure pattern behind nearly half the year's losses.
Read the full analysis →July 2026
A firmware build error gave Coldcard seeds as little as 40 bits of entropy for five years; attackers brute-forced the keyspace offline and swept $116M in BTC from more than 5,200 addresses in four waves.
Read the full analysis →Guru.fund, a delegated fund-management protocol on Ethereum, lost about $96K across seven transactions when a whitelisted deposit adapter let attackers make each vault approve and drain itself.
Read the full analysis →The Verus-Ethereum bridge was drained of $7.54M via a forged cross-chain import on July 23, 2026, two weeks after it refilled reserves recovered from May's $11.58M hack of the same import path.
Read the full analysis →How real-time DeFi security monitoring tools compare in 2026: enterprise platforms (Hypernative, Hexagate), inline firewalls (Forta Firewall, BlockSec), and self-serve machine-readable feeds (Defimon), by approach, coverage, integration, and pricing.
Read the full analysis →A production integration guide for the Defimon WebSocket feed: raw vs confirmed streams, reconnect handling, filtering alerts against your contracts and exposure, and what to automate versus page a human for.
Read the full analysis →Ostium, a perpetuals DEX on Arbitrum, lost $23.75M when an attacker with price-submission authority opened BTC longs at $5,000 and closed them near $60,000, draining the vault that backs every trade.
Read the full analysis →How cross-chain bridges get drained: validator key compromise, message verification bugs, false deposit events and custody failure, from Ronin and Wormhole to Shibarium and KelpDAO.
Read the full analysis →How DeFi price oracles get manipulated: spot-reserve pricing, missing update authorization, stale feeds and donation attacks, with real incidents and the on-chain patterns that expose them in real time.
Read the full analysis →What flash loan attacks are, why the loan itself is never the vulnerability, and how exploits that borrow nine figures with zero collateral are detected on-chain within a second.
Read the full analysis →November 2025
Yearn's yETH weighted stableswap pool exploited through numerical instability in fixed-point iteration solver. Attacker collapsed product term to zero, switching pool to constant-sum invariant, then triggered arithmetic underflow to mint 2.35×10⁵⁶ LP tokens.
Read the full analysis →Balancer V2 Composable Stable Pools exploited across multiple chains through rounding direction inconsistency in rate scaling logic. Attacker manipulated pool invariant to deflate BPT prices.
Read the full analysis →October 2025
Typus Finance lost $3.44M through oracle manipulation exploiting missing authorization check in custom oracle module. Attacker manipulated prices to drain TLP pool via arbitrage.
Read the full analysis →Abracadabra Money's third exploit in two years. Logic flaw in CauldronV4 contracts allowed $1.8M unbacked MIM borrowing via status flag reset.
Read the full analysis →September 2025
NewGold Protocol lost $2M through flash loan manipulation exploiting broken price oracle, faulty fee logic, and whitelisted dead address bypass.
Read the full analysis →Shibarium bridge drained for $3M through validator key compromise and flash loan manipulation. Attacker controlled 10/12 validators to authorize fraudulent checkpoints.
Read the full analysis →Defimon detects exploits on major chains the moment they execute and streams them to you: human-readable alerts in Telegram, or structured JSON over WebSocket for your own systems.
// signals $50/mo · websocket $200/mo · channel free
@DefimonAlerts